1. Cross-site scripting (reflected)
Severity: | Low |
Confidence: | Certain |
Host: | http://www.thebancorp.com |
Path: | /Contact-Us.asp |
GET /Contact-Us.asp HTTP/1.1 Host: www.thebancorp.com Accept: */* Accept-Language: en User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0) Connection: close Cookie: __utmz=50102755 Referer: http://www.google.com |
HTTP/1.1 200 OK Cache-Control: private Content-Length: 13914 Content-Type: text/html P3P: CP="ALL CUR OUR" X-Powered-By: ASP.NET Date: Fri, 31 Dec 2010 17:36:37 GMT Connection: close <html> <head> <Title>Contact Us - The Bancorp Inc.</Title> <META NAME="KEYWORDS" CONTENT="Bancorp, bank, FDIC-insured, commercial bank, financial services, branchless banking, healthcare banking ...[SNIP]... <input type="hidden" name="address" value="http://www.google ...[SNIP]... |